Jobs / engineering
Group Information Security Officer
TBAuctions · Amsterdam
About the role
We are looking for an experienced and hands-on Group Information Security Officer. In this position you design and implement Group information security standards across our business operations and monitor performance accordingly. You direct the Information Security Office, including information security representatives from our auction brands and our Group Risk and Compliance team.
As part of our strategy, we make significant investments in our auction management software and data platforms to make them the invisible engines of our business. We work with different platforms, some for a specific brand and some integrated with multiple brands. While learning from our integration efforts we continue building new features in the system at the same time. You have an essential role in this transition to ensure a security mindset among the business teams and developers and to ensure that security best practices are created and followed.
What you will do
To be successful, you should have expert analytical skills and in-depth knowledge of information security best practices to prevent and resolve a wide range of security threats. Top candidates will also be excellent communicators, able to train and educate our teams in various information security topics. To monitor performance against Group information security standards, you have a solid level of leadership and management skills allowing you to closely cooperate with Group and Regional functions.
In this postion you:
Own and continuously develop TBA’s information security strategy, policies, and standards across all regions and brands.
Act as the single point of accountability for information security, including cloud, application, infrastructure, and data security.
Lead risk assessments, threat modeling, and vulnerability management, maintain an up-to-date security risk register, and work in close cooperation with our Product and Tech teams to ensure that our network and data remain secure.
Own security incident response, including detection, escalation, communication, and post-incident reviews.
Help with future compliance, regulatory and standardization projects (e.g., ISO 27001/2, GDPR, NIS2).
Manage third-party and supplier security, including due diligence, ongoing reviews, and security clauses in contracts.
Drive security awareness and training across the organization.
Provide clear reporting to executive management, including risk posture, incidents, and remediation progress.